BILL ANALYSIS
SB 337
Page 1
Date of Hearing: June 30, 2009
ASSEMBLY COMMITTEE ON HEALTH
Dave Jones, Chair
SB 337 (Alquist) - As Amended: June 17, 2009
SENATE VOTE : 39-0
SUBJECT : Patient medical information: disclosure: reporting.
SUMMARY : Revises the time limits by which clinics, health
facilities, home health agencies, and hospices must inform
patients and the Department of Public Health (DPH) of
unauthorized access to, or use or disclosure of, patients'
medical information. Requires these entities to delay reports
at the request of a law enforcement agency or official stating
that compliance with the reporting requirement would be likely
to impede the law enforcement agency's activities, and specifies
a date upon which the delay shall end, with specific
requirements for oral, versus written requests for delays in
reporting. Specifically, this bill :
1)Requires a clinic, health facility, home health agency, or
hospice to report any unauthorized access to, or use or
disclosure of, a patient's medical information to DPH and to
the affected patient or patient's representative, no later
than five business days, instead of five days, after the
unlawful or unauthorized access, use, or disclosure has been
detected by the entity.
2)Requires the clinic, health facility, home health agency, or
hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical information
to DPH and the patient if a law enforcement agency or official
provides the entity with a written statement that notification
of patients would be likely to impede the law enforcement
agency's activities, and specifies a date upon the delay shall
end, not to exceed 60 days.
3)Requires the clinic, health facility, home health agency, or
hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical information
to DPH and the patient if a law enforcement agency or official
provides the entity with an oral statement and requires the
clinic, health facility, home health agency, or hospice to
SB 337
Page 2
document the statement including but not limited to the
identity of the enforcement agency or official, the date it
was made, and limit the delay to a date specified for the end
of the delay, not to exceed 30 calendar days from the date the
oral statement is made unless a written statement is received
during that time.
4)Requires that the written statement received during the 30
calendar days after an oral statement is made by the law
enforcement agency or official shall include a date the delay
is to end, not to exceed 60 days.
5)Allows a law enforcement agency or official to request an
extension of the original 60-day delay based upon a written
declaration that there exists a bona fide, ongoing,
significant criminal investigation of serious wrongdoing, that
notification of patients will undermine the law enforcement
agency's activities, and that specifies a date upon which the
delay shall end, not to exceed 60 days after the end of the
original 60-day period.
6)Requires a clinic, health facility, home health agency, or
hospice that is subject to a delay in reporting for law
enforcement purposes to report the unauthorized access to, or
use or disclosure of, the patient's medical information no
later than five business days, instead of five days, after the
date designated as the end of the delay.
EXISTING FEDERAL LAW :
1)Prohibits, under federal regulations implementing the federal
Health Insurance Portability and Accountability Act (HIPAA), a
health plan, health care clearinghouse, or a health care
provider, who transmits health information in electronic form
(covered entity), from using or disclosing protected health
information, for purposes other than medical treatment or
payment, or health care operations, as defined, without
written authorization of the patient, with exceptions.
2)Requires, under the American Recovery and Reinvestment Act
(ARRA) covered entities, and their business associates, to
provide notice of medical privacy breaches involving the
unauthorized acquisition, access, use, or disclosure of
protected health information to each individual whose
information has been subject to a breach within 60 days of the
SB 337
Page 3
discovery of the breach.
3)Provides that if a law enforcement official determines that
notice of a medical privacy breach would impede a criminal
investigation or cause damage to national security, the notice
shall be delayed, in a specified manner.
EXISTING STATE LAW :
1)Prohibits, under the Confidentiality of Medical Information
Act (CMIA), licensed or certified health care professionals,
clinics and health facilities, health plans, and contracting
entities, as defined, from disclosing or using a patient's
medical information for any purpose not necessary to provide
health care services to the patient and related administrative
functions, without first obtaining authorization from the
patient or the patient's representative, as specified, with
exceptions.
2)Provides for administrative fines and civil penalties for
persons and entities subject to the CMIA who negligently
disclose, or who knowingly and willfully obtain, disclose, or
use, medical information in violation of the CMIA, and
authorizes the Attorney General, any district attorney, any
county counsel acting pursuant to an agreement with the
district attorney, or a city attorney, to seek civil penalties
for violations.
3)Requires every provider of health care to establish and
implement administrative, technical, and physical safeguards
to protect the privacy of patients' medical information, and
requires every provider to reasonably safeguard confidential
medical information from any unauthorized access or unlawful
access, use, or disclosure.
4)Defines unauthorized access as the inappropriate review or
viewing of patient medical information without a direct need
for diagnosis, treatment, or other lawful use of the
information.
5)Requires a clinic, health facility, home health agency, or
hospice to report any unlawful or unauthorized access to, or
use or disclosure of, a patient's medical information to DPH
and to the affected patient or patient's representative, no
later than five days after the unlawful or unauthorized
SB 337
Page 4
access, use, or disclosure has been detected by the entity.
Allows DPH to assess a penalty of $100 for each day the
unlawful or unauthorized access, use, or disclosure is not
reported, following the initial five-day period, not to exceed
$250,000 per reported event.
6)Requires other persons or businesses that own or license
computerized data that includes personal information,
including medical information, to disclose any breach of the
security of the system to a resident whose unencrypted
personal information was acquired by an unauthorized person.
Provides that the notification may be delayed if a law
enforcement agency determines that notification will impede a
criminal investigation, as specified.
FISCAL EFFECT : According to the Senate Appropriations
Committee, pursuant to Senate Rule 28.8, negligible state costs.
COMMENTS :
1)PURPOSE OF THIS BILL . The author states that this bill is
intended to make two revisions to existing requirements that
health facilities notify patients and DPH when they detect any
unlawful or unauthorized access to, or use or disclosure of, a
patient's medical information. The existing requirements are
contained in SB 541 (Alquist), Chapter 605, Statutes of 2008.
The first is to revise the timeline for reporting such
breaches from five days to five business days. The second is
to allow for a delay in the reporting of such breaches when a
law enforcement agency or official makes a statement that it
would impede a law enforcement investigation of the breach.
The author states that these are reasonable revisions of the
reporting requirements for medical privacy breaches that are
consistent with the intent of the original legislation.
2)BACKGROUND . In response to several high profile incidents
involving unauthorized access to, and misuse or disclosure of,
patients' medical information, the legislature enacted two
bills in the 2007-08 Session, SB 541 (Alquist) and AB 211
(Jones), Chapter 606, Statutes of 2008. SB 541 requires
health care facilities to prevent unlawful or unauthorized
access to, use or disclosure of, patients' medical information
and to establish safeguards to protect the privacy of
patients' medical information. Among its provisions, SB 541
additionally requires a clinic, health facility, home health
SB 337
Page 5
agency, or hospice to report any unlawful or unauthorized
access to, or use or disclosure of, a patient's medical
information to DPH and to the affected patient or patient's
representative, no later than five days after the unlawful or
unauthorized access, use, or disclosure has been detected by
the entity. SB 541 authorizes DPH to assess a penalty of $100
for each day that an unlawful or unauthorized access, use, or
disclosure of medical information is not reported, beyond five
days after it has been detected, up to a maximum of $250,000
per reported event.
AB 211 requires health care providers to establish appropriate
safeguards to protect patients' medical information from
unauthorized or unlawful access, use, or disclosure. AB 211
establishes the Office of Health Information Integrity (OHII)
and gives it authority, upon a referral from DPH, to assess
administrative fines against any person or health care
provider for unauthorized use of patients' medical
information. AB 211 allows OHII to recommend that a licensing
board further investigate and discipline a health care
provider for violations of these provisions. Prior to
enactment of these two bills, the only remedy available to DPH
was to issue a notice of deficiency and require the facility
to implement a plan of correction. DPH indicated that while
it could refer individual providers within a health facility
to the relevant licensing board or to law enforcement, the
then-existing provisions of CMIA did not adequately address
unauthorized access to medical records, as opposed to
negligent or willful disclosure of the records. Another
factor precipitating passage of the two bills was press
coverage indicating that hospitals and other health care
organizations commonly use patients' information for
fundraising efforts without their express permission.
DPH reports that since January 1, 2009, when SB 541 took effect,
it has substantiated 18 cases of breaches of medical
confidentiality involving health facilities.
Under the medical privacy provisions of the recently enacted
federal economic stimulus bill, the American Recovery and
Reinvestment Act (ARRA), entities that transmit health
information in an electronic form are required to provide
notice of a medical privacy breach to an individual whose
information has been subject to a breach, within 60 days of
the discovery of the breach. The 60-day requirement is
SB 337
Page 6
delayed in the case that a law enforcement official determines
that notice of a medical privacy breach would impede a
criminal investigation or cause damage to national security.
However, ARRA provides that state medical privacy breach
notification laws that are more protective of medical privacy
(such as the notification requirements in California law) are
not preempted.
3)RELATED LEGISLATION .
a) SB 368 (Maldonado) allows OHII to audit the procedures
and records of a health care provider at any time in order
to determine the provider's compliance with requirements to
establish and implement appropriate administrative,
technical, and physical safeguards to protect the privacy
of patient's medical information, and to reasonably
safeguard confidential medical information from any
unauthorized access or unlawful access, use, or disclosure.
SB 368 is currently in the Senate Health Committee; the
author has made this a two-year bill.
b) AB 1011 (Jones) by April 1, 2010, requires OHII to
report to the Legislature on the impact of federal changes
related to health care technology and the privacy of health
and medical information, including recommendations for
statutory changes to ensure that California's medical
privacy laws are minimally compliant with or exceed federal
privacy laws. AB 1011 is pending in the Senate.
4)PRIOR LEGISLATION .
a) AB 211 (Jones), establishes OHII to ensure the
enforcement of state confidentiality of medical
information, to impose administrative fines for
unauthorized use of medical information upon referral from
DPH, and requires providers of health care to establish and
implement appropriate administrative, technical, and
physical safeguards to protect the privacy of patient's
medical information.
b) SB 1301 (Alquist), Chapter 647, Statutes of 2006,
requires general acute care hospitals, acute psychiatric
hospitals, and special hospitals to report adverse events
to the Department of Health Services (now DPH) no later
than five days after the event has been detected, or in the
SB 337
Page 7
case of an urgent or emergent threat, no later than 24
hours after the adverse event has been detected. Requires
DPH, by January 1, 2013, to provide information regarding
reports of substantiated adverse events and the outcomes of
inspections on its Web site.
c) SB 1312 (Alquist), Chapter 895, Statutes of 2006,
authorizes DPH to assess administrative penalties on
hospitals based on deficiencies constituting immediate
jeopardy to the health and safety of a patient. SB 1312
requires inspections and investigations of long-term care
facilities certified by the Medicare or Medicaid program to
determine compliance with federal standards and California
statutes and regulations. SB 1312 eliminates existing law
that provides an exemption for specified health care
facilities from periodic inspections by DPH.
5)SUPPORT . The California Hospital Association (CHA) states
that many hospitals operate manual systems to assign patient
identification numbers and in those cases, identifying and
extracting data regarding patients whose medical information
has been improperly accessed, used, or disclosed would be a
labor intensive process that could take more than five days,
as currently provided in law. CHA supports the change to five
business days for reporting, but notes that it would still be
stricter than federal law. CHA also states that the
provisions of the bill allowing a delay in reporting at the
request of law enforcement are similar to those adopted as
part of ARRA, and argues that patient privacy laws that
deviate extensively from federal laws place additional burdens
and expense on hospitals, which could be better utilized
providing care to patients.
6)LAW ENFORCEMENT EXCEPTION . The delay in notice in the case of
a law enforcement investigation in this bill is narrowly
crafted to balance patient protection and law enforcement
interest. The language providing for an extension of the
60-day delay at the request of law enforcement requires a
declaration that there exists an ongoing significant criminal
investigation of "serious wrongdoing." To be consistent with
the author's intent, this bill should be amended to clarify
that the serious wrongdoing is limited to unlawful or
unauthorized access so that it is not interpreted as authority
for law enforcement to have access to records without notice
to the patient for any other reason.
SB 337
Page 8
REGISTERED SUPPORT / OPPOSITION :
Support
California Hospital Association
Opposition
None on file.
Analysis Prepared by : Marjorie Swartz / HEALTH / (916)
319-2097